VYPR

rpm package

opensuse/netty&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/netty&distro=openSUSE%20Tumbleweed

Vulnerabilities (102)

  • CVE-2026-93574MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsing of the chunk size can lead to HTTP request smuggling.

  • CVE-2026-93562MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker can inject arbitrary HTTP requests, potentially bypassing s

  • CVE-2026-93579MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HTTP/2 stack. This vulnerability allows a remote attacker to inject prohibited characters, such as NUL, Line Feed, and Carriage Return, into HTTP/2 header field values due to insufficient validation. When these values cross an HTTP/2 to HTTP/1.1 transl

  • CVE-2026-93576HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed (LF) characters in the SMTP command-name field. A remote attacker, if an application routes untrusted input into this field, can embed CR/LF characters to injec

  • CVE-2026-93573MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` header validation by splitting the `Transfer-Encoding` field across multiple headers, with the last field containing a non-final transfer coding like `gzip` or

  • CVE-2026-93569HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 conversion process. When an HTTP/1 request includes both an absolute-form request-target and a conflicting Host header, Netty incorrectly prioritizes the Host head

  • CVE-2026-93568HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTTP/3 Extended CONNECT requests. Netty's HTTP-object conversion path incorrectly processes these requests as regular HTTP/1.1 CONNECT requests, leading to a loss

  • CVE-2026-93567HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly uses the Host header instead of the CONNECT authority-form request-target for the tunnel authority. A remote attacker can exploit this by supplying a different H

  • CVE-2026-93566MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that includes control characters within the chunk-size line. This bypasses the intended strict validation, allowing the attacker to inject arbitrary HTTP requests. This vul

  • CVE-2026-93565HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes from method tokens in Real-Time Streaming Protocol (RTSP) requests. A remote attacker can exploit this by sending a specially crafted RTSP request, leading to met

  • CVE-2026-93564HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticated attacker to send specially crafted PROXY-protocol v2 headers. This can lead to memory exhaustion, resulting in a Denial of Service (DoS) for the affected sys

  • CVE-2026-93558HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnerability by using HTTP/1.1 pipelining to send requests faster than the application can respond. This leads to an unbounded growth of a per-connection queue, consu

  • CVE-2026-93560HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-length header exceeding the maximum integer value. This integer truncation vulnerability could lead to an infinite decode loop, causing a Denial of Service (DoS)

  • CVE-2026-93492MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames with a very large MAX_HEADER_TABLE_SIZE. This causes the HpackEncoder to store an excessive number of unique headers, leading to increased CPU usage and memory co

  • CVE-2026-93491HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipelining HTTP/1.1 requests on a single connection and withholding reads. This action causes the methodOverflowQueue to grow without limit, leading to unbounded heap

  • CVE-2026-93488HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because localConcurrentStreams defaults to Integer.MAX_VALUE and the handler provides no API to change it. A remote peer can open a SPDY connection and send a large nu

  • CVE-2026-93578MedSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSPSigning' Extended Key Usage (EKU) in OCSP responder certificates. A remote attacker, holding any valid certificate issued by the same Certificate Authority (CA)

  • CVE-2026-93575HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted MQTT CONNECT packet. The decoder fails to properly validate the 'Properties Length' against the 'Remaining Length', allowing an attacker to by

  • CVE-2026-93572HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sending specially crafted nested Redis (RESP) array headers. This can cause the `RedisArrayAggregator` to eagerly preallocate a large amount of heap memory, leading t

  • CVE-2026-93563HigSep 18, 2026
    affected < 4.1.138-1.1fixed 4.1.138-1.1

    A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-middle (MITM) SMTP server, could exploit this by sending a specially crafted, unbounded multi-line SMTP response without a terminator. This vulnerability leads to u

Page 1 of 6